Cyware Weekly Threat Intelligence - August 28–01

Weekly Threat Briefing • September 1, 2023
Weekly Threat Briefing • September 1, 2023
The FBI has managed to neutralize the activity of yet another notorious malware network. This week, the agency announced the dismantling of the QakBot infrastructure that was used to infect over 700,000 computers worldwide, with more than 200,000 located only in the U.S. Besides this, there’s a piece of good news for victims affected by Key Group ransomware. They can now decrypt encrypted files using a free decryption tool that is built on flaws found in the ransomware’s encryption process.
Moving on to data breaches disclosed this week, three cryptocurrency platforms were in the crosshairs of a SIM-swapping attack that enabled attackers to gain unauthorized access to the sensitive details of their claimants. Separately, a reputed clothing retailer, Forever 21, and a meal delivery service, PurFoods, were notified of data breaches that impacted the personal information of millions of customers.
Meanwhile, a lesser-known threat actor group Earth Estries came under the lens of researchers for its involvement in a cyberespionage campaign targeting governments and IT companies. There were updates on new Android malware families—MMRat and Infamous Chisel—spotted in different campaigns. While MMRat was used to target mobile users in Southeast Asia, Infamous Chisel infected the Android devices of the Ukrainian military.